CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52750  CVE-2011-4838  Candidate  JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  Assigned (20111215)  None (candidate not yet proposed)    View
53006  CVE-2011-5094  Candidate  ** DISPUTED ** Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.  Assigned (20120616)  None (candidate not yet proposed)    View
53262  CVE-2012-0019  Candidate  Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.  Assigned (20111109)  None (candidate not yet proposed)    View
53518  CVE-2012-0275  Candidate  Heap-based buffer overflow in Photoshop.exe in Adobe Photoshop CS5 12.x before 12.0.5, CS5.1 12.1.x before 12.1.1, and CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted TIFF image with SGI24LogLum compression.  Assigned (20111230)  None (candidate not yet proposed)    View
53774  CVE-2012-0531  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise Portal component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect integrity via unknown vectors related to Enterprise Portal.  Assigned (20120111)  None (candidate not yet proposed)    View

Page 1199 of 20943, showing 5 records out of 104715 total, starting on record 5991, ending on 5995

Actions